Threat Database Trojans Trojan.Agent.GBM

Trojan.Agent.GBM

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,778
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: October 13, 2025
Last Seen: May 24, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.GBM on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and secure your system.

What Is Trojan.Agent.GBM?

Trojan.Agent.GBM is a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate software to gain unauthorized access to a computer system. The name "Trojan.Agent.GBM" suggests that it is a generic detection for a Trojan-type threat, and its specific characteristics and behaviors may vary. Trojans are known for their ability to evade detection by traditional security measures, making them particularly dangerous as they can lead to a wide range of malicious activities, including data theft, spyware installation, and ransomware attacks.

How Trojan.Agent.GBM Operates

Once installed on a system, Trojan.Agent.GBM can operate in various ways, depending on its intended purpose. It may create backdoors for remote access, allowing hackers to control the infected computer, steal sensitive information, or use the system as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming. Trojans often exploit vulnerabilities in software or manipulate users into executing them, either by disguising themselves as useful applications or attaching themselves to legitimate programs. Understanding how Trojans operate is crucial for taking effective measures to prevent and remove them.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to their stealthy nature. However, several symptoms may indicate the presence of Trojan.Agent.GBM or similar malware. These include unexpected changes in system performance, such as slow downs or frequent crashes, appearance of unwanted programs or toolbars, unusual network activity, and pop-ups or other signs of adware. If you suspect that your system is infected, it is crucial to act quickly to minimize potential damage.

How to Remove Trojan.Agent.GBM

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any associated malware.
  3. Uninstall any suspicious programs that were installed around the time the malware was detected. Be cautious and only remove applications that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that all components of the Trojan have been removed.

Conclusion

Removing Trojan.Agent.GBM requires careful and immediate action to prevent further damage to your system and protect your personal data. By understanding the nature of this threat and following the steps outlined for removal, you can help secure your computer against this and similar threats. It is also essential to maintain good cybersecurity practices, including keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening emails or downloading files from the internet. Vigilance and proactive measures are key to protecting against malware and maintaining the security and integrity of your digital environment.

Analysis Report

General information

Family Name: Trojan.Agent.GBM
Signature status: Self Signed

Known Samples

MD5: 6b725d2554af8516f9c2454563a313a4
SHA1: c21442c3bd571de7b9493593a57ea6cbcc65c84e
SHA256: B18A37C71554DAEFF98F1BC1F573194FF19F341F460FBEA3E539119492F5BA13
File Size: 367.34 KB, 367344 bytes
MD5: 41b3d8718a5cc99ec45ee2aabdaedd21
SHA1: 16543d32315576dbfd5e66341aa81073a8ec5186
SHA256: 661094C71B141900435BC2C676F2CD906BA49A8E8F20A864FB7DB266589043A4
File Size: 385.26 KB, 385264 bytes
MD5: 1e2cffd0312ec9352f3be5791931c078
SHA1: db8dc1c204404aeb51c6910c7367c4aa88d0a9b3
SHA256: E06C667AA3DA694C8CFBB7847CE6FEA53AE4450708080A801EDA34A7FD4B4E95
File Size: 384.75 KB, 384752 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name KillerMacros
File Description BoomBang Assistant Tool
File Version 3.0.0.0
Internal Name KillerMacros
Legal Copyright 7hrashcr
Original Filename KillerMacros.exe
Product Name KillerMacros
Product Version 3.0.0.0

Digital Signatures

Signer Root Status
KillerMacros KillerMacros Self Signed
KislerMacros KislerMacros Hash Mismatch

File Traits

  • x64

Block Information

Total Blocks: 556
Potentially Malicious Blocks: 19
Whitelisted Blocks: 411
Unknown Blocks: 126

Visual Map

? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x ? x x 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? 0 0 ? 0 ? 0 x ? x 0 x x ? ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? 0 0 0 0 ? 0 ? ? ? 0 ? x ? ? ? ? ? 0 ? 0 0 ? 0 ? ? 0 0 ? ? x ? ? ? ? ? ? ? ? 0 0 x ? ? ? ? ? ? 0 0 0 x 0 ? 0 ? ? 0 ? ? ? x x ? ? ? 0 ? 0 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 0 0 0 ? 0 x 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\downloads\phrases.txt Generic Write,Read Attributes
c:\users\user\downloads\settings.txt Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Network Info Queried
  • GetAdaptersInfo
User Data Access
  • GetUserName
Encryption Used
  • BCryptOpenAlgorithmProvider
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpReceiveResponse
  • WinHttpSendRequest
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...